CVE-2026-86681: Broken Access Control vulnerability
Published Sep 23, 2026
·Updated
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope.
Affected Software
1 affected component
Zohocorp ManageEngine Applications Manager<=182200
Event History
Sep 23, 2026
CVE Published
via MITRE·01:17 PM
Data Sourced
via MITRE·01:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated low-privileged user can exploit it. Exploitation requires access to Applications Manager but does not require user interaction.
2
What actions could an attacker perform?
A low-privileged user could execute administrator-configured MBean actions on monitors that are outside that user's assigned scope. The stated impact includes high integrity impact, with limited confidentiality and availability impact.
3
Which versions are affected?
ManageEngine Applications Manager version 182200 and earlier are affected.